PatchSiren cyber security CVE debrief
CVE-2026-88994 All Bootstrap Blocks CVE debrief
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached.
- Vendor
- All Bootstrap Blocks
- Product
- All Bootstrap Blocks
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-09-18
Who should care
WordPress administrators, security teams, and developers using the All Bootstrap Blocks plugin should assess exposure and prioritize remediation to prevent arbitrary file inclusion and execution.
Why it matters
This vulnerability allows users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP code. WordPress administrators and security teams should assess exposure and prioritize remediation to prevent potential security breaches.
- Arbitrary local file inclusion and disclosure of file contents
- Execution of PHP code where a local file containing PHP code can be reached
- Potential for privilege escalation through exploitation of vulnerable plugin
Technical summary
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled.
Defensive priority
Assess exposure and prioritize remediation for WordPress installations using the All Bootstrap Blocks plugin, especially those with contributor-level access or higher.
Recommended defensive actions
- Assess exposure by checking if the All Bootstrap Blocks plugin is installed and enabled on WordPress installations
- Verify if the Lightspeed subsystem is enabled, as exploitation requires this feature
- Restrict contributor-level access and above to prevent arbitrary file inclusion and execution
- Consider updating the plugin to a version that addresses this vulnerability, if available
- Perform a thorough review of system logs to detect potential exploitation attempts
- Implement additional monitoring for unusual file access or execution patterns
- Document and track remediation efforts for auditing and compliance purposes
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact and mitigation strategies.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88994 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88994
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88994 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88994
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/55b1f0b1-dc15-45d4-beb2-4d1d7a9fe3dd/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.